– %WINDIR%\tsrv.dll Further investigation pointed out that this file is malware, too. Detected as: Worm/Warezov.Q.1

– %SYSDIR%\hpzl449c14b7.exe Further investigation pointed out that this file is malware, too. Detected as: Worm/Warezov.Q.1

– %SYSDIR%\msji449c14b7.dll Further investigation pointed out that this file is malware, too. Detected as: Worm/Stration

– %SYSDIR%\cmut449c14b7.dll Further investigation pointed out that this file is malware, too. Detected as: Worm/Warezov.Q

It tries to download a file:

– The location is the following: • http://yuhadefunjinsa.com/chr/grw/********** It is saved on the local hard drive under: %TEMPDIR%\~%number%.tmp Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too.

Registry

The following registry key is added in order to run the process after reboot:

It contains an integrated SMTP engine in order to send emails. A direct connection with the destination server will be established. The characteristics are described in the following:

From: Generated addresses. Please do not assume that it was the sender's intention to send this email to you. He might not know about his infection or might not even be infected at all. Furthermore it is possible that you will receive bounced emails telling you that you are infected. This might also not be the case.

From: sec@%recipient's domain%Subject: Mail server report. Body: • Mail server report. Our firewall determined the e-mails containing worm copies are being sent from your computer. Nowadays it happens from many computers, because this is a new virus type (Network Worms). Using the new bug in the Windows, these viruses infect the computer unnoticeably. After the penetrating into the computer the virus harvests all the e-mail addresses and sends the copies of itself to these e-mail addresses Please install updates for worm elimination and your computer restoring. Best regards, Customers support serviceAttachment: • Update-KB%number%-x86.exe

From: secur@%recipient's domain%Subject: Mail server report. Body: • Mail server report. Our firewall determined the e-mails containing worm copies are being sent from your computer. Nowadays it happens from many computers, because this is a new virus type (Network Worms). Using the new bug in the Windows, these viruses infect the computer unnoticeably. After the penetrating into the computer the virus harvests all the e-mail addresses and sends the copies of itself to these e-mail addresses Please install updates for worm elimination and your computer restoring. Best regards, Customers support serviceAttachment: • Update-KB%number%-x86.exe

From: serv@%recipient's domain%Subject: Mail server report. Body: • Mail server report. Our firewall determined the e-mails containing worm copies are being sent from your computer. Nowadays it happens from many computers, because this is a new virus type (Network Worms). Using the new bug in the Windows, these viruses infect the computer unnoticeably. After the penetrating into the computer the virus harvests all the e-mail addresses and sends the copies of itself to these e-mail addresses Please install updates for worm elimination and your computer restoring. Best regards, Customers support serviceAttachment: • Update-KB%number%-x86.exe

Body: The body of the email is one of the lines: • Mail transaction failed. Partial message is available. • The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment • The message contains Unicode characters and has been sent as a binary attachment

Attachment: The filename of the attachment is constructed out of the following: